Skip to content

MCPA-2026-0012

highrce-vectorsCVSS 8.4

Flyto2 Core unauthenticated command execution via HTTP MCP execute_module (CVE-2026-55786)

flyto-core versions 2.26.2 before 2.26.4 expose an execute_module operation on the HTTP MCP surface without authentication: a caller who can reach the HTTP listener can invoke arbitrary Flyto modules, including ones that run shell commands, without any credential. Fixed in 2.26.4.

Affected packages

EcosystemPackageAffected versions
pypiflyto-core
>= 2.26.2, < 2.26.4

Identifiers

CVE-2026-55786GHSA-h9f9-h6gm-wc85PYSEC-2026-2482CWE-78CWE-306

References

Timeline

  • Published: 2026-07-06

← All advisories